plugin

Rich Reviews Vulnerabilities

9 known security issues reported for the Rich Reviews WordPress plugin. Most recent disclosed Oct 16, 2024.

3 high

Running Rich Reviews on your site? Check whether your installed version is affected.

Scan your site free

Rich Reviews by Starfish [rich-reviews] < 1.8.0 (closed)

unknown

[en] The Rich Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the POST body 'update' parameter in versions up to, and including, 1.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...

Affected:
up to 1.8.0
Fixed in:
1.8.0
Disclosed:
Oct 16, 2024

CVE-2019-25216 on NVD →

Rich Reviews by Starfish [rich-reviews] < 1.9.15 (closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Rich Reviews by Starfish plugin <= 1.9.14 at WordPress allows an attacker to delete reviews.

Affected:
up to 1.9.15
Fixed in:
1.9.15
Disclosed:
Aug 5, 2022

CVE-2021-36861 on NVD →

Rich Reviews by Starfish <= 1.9.14 - Cross-Site Request Forgery

high

The Rich Reviews by Starfish plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.14. This is due to missing nonce validation on the process_bulk_action() function. This makes it possible for unauthenticated attackers to bulk process reviews via a forged request granted...

CVSS:
8.8
Affected:
up to 1.9.14
Fixed in:
1.9.15
Disclosed:
Aug 2, 2022

CVE-2021-36861 on NVD →

Rich Reviews by Starfish [rich-reviews] < 1.9.6 (closed)

unknown

[en] The Rich Reviews by Starfish WordPress plugin before 1.9.6 does not properly validate the orderby GET parameter of the pending reviews page before using it in a SQL statement, leading to an authenticated SQL injection issue

Affected:
up to 1.9.6
Fixed in:
1.9.6
Disclosed:
Dec 27, 2021

CVE-2021-24753 on NVD →

Rich Reviews by Starfish <= 1.9.5 - SQL Injection

high

The Rich Reviews by Starfish WordPress plugin before 1.9.6 does not properly validate the orderby GET parameter of the pending reviews page before using it in a SQL statement, leading to an authenticated SQL injection issue

CVSS:
8.8
Affected:
up to 1.9.6
Fixed in:
1.9.6
Disclosed:
Nov 29, 2021

CVE-2021-24753 on NVD →

Rich Reviews by Starfish [rich-reviews] < 1.7.5 (closed)

unknown

Unauthenticated Plugin Options Update vulnerability found in WordPress Rich Reviews plugin (versions <= 1.7.4).

Affected:
up to 1.7.5
Fixed in:
1.7.5
Disclosed:
Sep 25, 2019

Rich Reviews <= 1.7.4 - Stored Cross-Site Scripting

high

The Rich Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the POST body 'update' parameter in versions up to, and including, 1.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wi...

CVSS:
7.2
Affected:
up to 1.7.4
Fixed in:
1.8.0
Disclosed:
Sep 24, 2019

CVE-2019-25216 on NVD →

Rich Reviews by Starfish [rich-reviews] < 1.8.0 (closed)

unknown

The Rich Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the POST body 'update' parameter in versions up to, and including, 1.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wi...

Affected:
up to 1.8.0
Fixed in:
1.8.0
Disclosed:
Sep 24, 2019

Rich Reviews by Starfish [rich-reviews] < 1.8.0 (closed)

unknown

This issue was found to be actively exploited in the wild by security vendor Wordfence. Refer to the references for further details.

Affected:
up to 1.8.0
Fixed in:
1.8.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database